5.5

CVSS3.1

CVE-2023-53618 - btrfs: reject invalid reloc tree root keys with stack dump

In the Linux kernel, the following vulnerability has been resolved: btrfs: reject invalid reloc tree root keys with stack dump [BUG] Syzbot reported a crash that an ASSERT() got triggered inside prepare_to_merge(). That ASSERT() makes sure the reloc tree is properly pointed back by its subvolume…

πŸ“… Published: Oct. 7, 2025, midnight πŸ”„ Last Modified: Feb. 5, 2026, 2:58 p.m.

5.5

CVSS3.1

CVE-2023-53632 - net/mlx5e: Take RTNL lock when needed before calling xdp_set_features()

In the Linux kernel, the following vulnerability has been resolved: net/mlx5e: Take RTNL lock when needed before calling xdp_set_features() Hold RTNL lock when calling xdp_set_features() with a registered netdev, as the call triggers the netdev notifiers. This could happen when switching from upl…

πŸ“… Published: Oct. 7, 2025, midnight πŸ”„ Last Modified: Feb. 3, 2026, 10:26 p.m.

5.5

CVSS3.1

CVE-2023-53624 - net/sched: sch_fq: fix integer overflow of "credit"

In the Linux kernel, the following vulnerability has been resolved: net/sched: sch_fq: fix integer overflow of "credit" if sch_fq is configured with "initial quantum" having values greater than INT_MAX, the first assignment of "credit" does signed integer overflow to a very negative value. In thi…

πŸ“… Published: Oct. 7, 2025, midnight πŸ”„ Last Modified: Feb. 5, 2026, 2:32 p.m.

5.5

CVSS3.1

CVE-2022-50511 - lib/fonts: fix undefined behavior in bit shift for get_default_font

In the Linux kernel, the following vulnerability has been resolved: lib/fonts: fix undefined behavior in bit shift for get_default_font Shifting signed 32-bit value by 31 bits is undefined, so changing significant bit to unsigned. The UBSAN warning calltrace like below: UBSAN: shift-out-of-boun…

πŸ“… Published: Oct. 7, 2025, midnight πŸ”„ Last Modified: March 17, 2026, 2:06 p.m.

5.5

CVSS3.1

CVE-2022-50520 - drm/radeon: Fix PCI device refcount leak in radeon_atrm_get_bios()

In the Linux kernel, the following vulnerability has been resolved: drm/radeon: Fix PCI device refcount leak in radeon_atrm_get_bios() As comment of pci_get_class() says, it returns a pci_device with its refcount increased and decreased the refcount for the input parameter @from if it is not NULL…

πŸ“… Published: Oct. 7, 2025, midnight πŸ”„ Last Modified: March 17, 2026, 2:13 p.m.

8.5

CVSS3.1

CVE-2025-44824 -

Nagios Log Server before 2024R1.3.2 allows authenticated users (with read-only API access) to stop the Elasticsearch service via a /nagioslogserver/index.php/api/system/stop?subsystem=elasticsearch call. The service stops even though "message": "Could not stop elasticsearch" is in the API response.…

πŸ“… Published: Oct. 7, 2025, midnight πŸ”„ Last Modified: Nov. 6, 2025, 4:40 p.m.

5.5

CVSS3.1

CVE-2023-53644 - media: radio-shark: Add endpoint checks

In the Linux kernel, the following vulnerability has been resolved: media: radio-shark: Add endpoint checks The syzbot fuzzer was able to provoke a WARNING from the radio-shark2 driver: ------------[ cut here ]------------ usb 1-1: BOGUS urb xfer, pipe 1 != type 3 WARNING: CPU: 0 PID: 3271 at dr…

πŸ“… Published: Oct. 7, 2025, midnight πŸ”„ Last Modified: Feb. 3, 2026, 10:29 p.m.

5.5

CVSS3.1

CVE-2023-53635 - netfilter: conntrack: fix wrong ct->timeout value

In the Linux kernel, the following vulnerability has been resolved: netfilter: conntrack: fix wrong ct->timeout value (struct nf_conn)->timeout is an interval before the conntrack confirmed. After confirmed, it becomes a timestamp. It is observed that timeout of an unconfirmed conntrack: - Set …

πŸ“… Published: Oct. 7, 2025, midnight πŸ”„ Last Modified: Feb. 3, 2026, 10:25 p.m.

6.7

CVSS3.1

CVE-2025-62186 -

Ankitects Anki before 25.02.5 allows a crafted shared deck on Windows to execute arbitrary commands when playing audio because of URL scheme mishandling.

πŸ“… Published: Oct. 7, 2025, midnight πŸ”„ Last Modified: Oct. 10, 2025, 4:20 p.m.

6.7

CVSS3.1

CVE-2025-62185 -

In Ankitects Anki before 25.02.5, a crafted shared deck can place a YouTube downloader executable in the media folder, and this is executed for a YouTube link in the deck. The executable name could be youtube-dl.exe or yt-dlp.exe or yt-dlp_x86.exe.

πŸ“… Published: Oct. 7, 2025, midnight πŸ”„ Last Modified: Oct. 10, 2025, 4:21 p.m.
Total resulsts: 349182
Page 3535 of 34,919
Β« previous page Β» next page
Filters